What happened
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
Affected versions
Red Hat build of Keycloak 26.4: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · Red-Darkin/CVE-2026-18963-keycloakCVE-2026-18963ExploitPython★ 16⑂ 3Code indexedUpdated 26 Aug 2026Red-Darkin2026-08-24CandidateCVE-Intel · Snizi/CVE-2026-18963-ExploitExploit for KeyCloak CVE-2026-18963BypassPython★ 24⑂ 6Code indexedUpdated 26 Aug 2026Tags: account-takeover, authentication-bypass, cve-2026-18963, exploit, keycloak, oauth2, penetration-testing, pocSnizi2026-08-20CandidateCVE-Intel · prot0tw/Keycloak_CVE-2026-18963_PoCThis repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).PoCPython★ 13⑂ 0Code indexedUpdated 26 Aug 2026prot0tw2026-08-25CandidateCVE-Intel · T0w0T/POC-CVE-2026-18963PoCPython★ 2⑂ 0Code indexedUpdated 25 Aug 2026T0w0T2026-08-24CandidateCVE-Intel · debugactiveprocess/CVE-2026-18963Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.Exploit★ 0⑂ 0Updated 25 Aug 2026debugactiveprocess2026-08-25CandidateCVE-Intel · gman0x00/keycloak-CVE-2026-18963PoC, Dockerfile playground and root cause from patch diff analysis.PoCPython★ 0⑂ 0Code indexedUpdated 25 Aug 2026gman0x002026-08-25CandidateCVE-Intel · kyos-public/keycloak-cve-2026-18963-huntHunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak databaseExploit★ 11⑂ 1Updated 25 Aug 2026Tags: cve, incident-response, keycloak, postgresql, securitykyos-public2026-08-20CandidateCVE-Intel · minh3102011/CVE-2026-18963_analystExploit★ 0⑂ 0Updated 24 Aug 2026minh31020112026-08-24CandidatePoC-in-GitHub · BlackHatExploitation/Exploit-For-CVE-2026-18963Exploit for CVE-2026-18963 by BlackHatExploitation★ 0BlackHatExploitation2026-08-25CandidatePoC-in-GitHub · alt3kx/CVE-2026-18963CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector★ 3alt3kx2026-08-27CandidatePoC-in-GitHub · M4xSec/My-ExploitsMetasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).★ 1M4xSec2026-08-31CandidatePoC-in-GitHub · EQSTLab/CVE-2026-18963Keycloak reset-credentials flow bypass★ 2EQSTLab2026-09-01CandidateSploitusKeycloak reset-credentials bypass leading to account takeover via exploit.0xlyvio2026-09-05T20:53:12Candidate0xlyvio/CVE-2026-18963-keycloakKeycloak reset-credentials bypass leading to account takeover via exploit.0xlyvio2026-09-05T20:53:12CandidateSource timeline
Discovered through CVE-IntelView source ↗
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.